Post-quantum secure transmission method, system and device of 5G user plane, and medium

By deploying a security layer on the 5G user plane data transmission path and utilizing post-quantum cryptography's secure handshake and encryption algorithms, a quantum-resistant secure channel is established, solving the security problem of 5G user plane data transmission in a quantum computing environment and achieving data confidentiality and integrity protection.

CN121509995APending Publication Date: 2026-02-10THE UNIV OF NOTTINGHAM NINGBO CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511629269.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-07
Publication Date
2026-02-10

AI Technical Summary

Technical Problem

Existing 5G user plane data transmission lacks quantum security against quantum computing technology and is vulnerable to spoofing attacks and data tampering.

Method used

A security layer is deployed on the 5G user plane data transmission path. A quantum-resistant secure channel is established through a security protocol handshake using post-quantum cryptography to perform key negotiation and identity authentication. Post-quantum cryptographic algorithms are used to encrypt and decrypt data packets to ensure the confidentiality and integrity of data transmission.

Benefits of technology

It effectively resists quantum computing attacks, ensures the confidentiality and integrity of user business data, prevents data tampering, has good backward compatibility and feasibility, and reduces deployment costs and complexity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121509995A_ABST
    Figure CN121509995A_ABST
Patent Text Reader

Abstract

The invention provides a post-quantum secure transmission method, system and device of a 5G user plane and a medium, and relates to the technical field of communication, the method is applied to the 5G user plane, and a security layer is deployed on a user data transmission path between a base station of the 5G user plane and a core network user plane function; the method comprises the following steps: after a 5G user plane and a base station access a network, the base station and a core network user plane function execute a security protocol handshake process through a security layer, and an anti-quantum security channel is established; when the base station obtains user data, the base station encapsulates service data according to a preset protocol to obtain a transmission data packet; the base station encrypts the transmission data packet by using the security layer to obtain an encrypted data packet; and the core network user plane function decrypts and forwards the encrypted data packet by using the security layer. According to the invention, by introducing a security layer and an anti-quantum security channel, a transmission mechanism integrating anti-quantum key agreement, quantum-level encryption protection, integrity verification and identity authentication is constructed.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of communication technology, in particular to a post-quantum secure transmission method, system and device for a 5G user plane and a medium. BACKGROUND

[0002] As a core link of 5G network data transmission, the 5G user plane undertakes the key task of service data transmission between user equipment (UE) and data network, and its security is directly related to user privacy protection, service data integrity and network operation stability, and is one of the key research directions of security protection in the field of 5G communication technology. In the 5G standard given by 3GPP, the IPSec network layer security protocol is usually recommended to be deployed in the 5G user plane data transmission to protect data confidentiality and integrity.

[0003] In related technologies, when facing the current rapid development of quantum computing technology, the deployment in the 5G user plane data transmission usually lacks quantum security, cannot resist the cracking threat of quantum computers to traditional cryptographic algorithms, and is prone to cause the risk of fake attacks and data tampering in the data transmission process. SUMMARY

[0004] The problem solved by the present application is how to improve the security of post-quantum transmission for the 5G user plane.

[0005] To solve the above problems, the present application provides a post-quantum secure transmission method, system and device for a 5G user plane and a medium.

[0006] In a first aspect, the present application provides a post-quantum secure transmission method for a 5G user plane, which is applied to a user data transmission path between a base station of the 5G user plane and a core network user plane function, and a security layer is deployed on the user data transmission path; the post-quantum secure transmission method for the 5G user plane comprises: After the base station and the 5G core network user plane function access the network, performing a handshake process of a security protocol through the security layer to establish an anti-quantum secure channel; Accepting service data from a user through the base station, and encapsulating the service data according to a preset protocol to obtain a transmission data packet of the service data; Encrypting the transmission data packet through the security layer by the base station to obtain an encrypted data packet, and sending the encrypted data packet to the core network user plane function; Decrypting and forwarding the encrypted data packet through the security layer by the core network user plane function.

[0007] Optionally, after the base station and the 5G core network user plane function access the network, the handshake process of the security protocol is performed through the security layer to establish the anti-quantum secure channel, comprising: When the base station and the 5G core network user plane function access the network, a handshake process corresponding to a security protocol of a data packet transmission layer integrated by the security layer is determined according to the security protocol; The handshake process of the security protocol is executed by the security layer, and bidirectional identity authentication is performed; When the bidirectional identity authentication is completed, an anti-quantum secure channel is established by using encryption algorithm parameters corresponding to the security protocol.

[0008] Optionally, the handshake process of the security protocol is executed by the security layer, and bidirectional identity authentication is performed, including: Identity information of the base station and the core network user plane function is exchanged based on the security protocol, and a post-quantum cryptographic algorithm is called by the security layer; Bidirectional identity authentication is performed according to the identity information of the base station and the core network user plane function by using the post-quantum cryptographic algorithm.

[0009] Optionally, the base station receives service data from a user, and encapsulates the service data according to a preset protocol to obtain a transmission data packet of the service data, including: The base station receives the service data from the user, and the service data is communication data between the user equipment and a data network; The service data is encapsulated according to a tunnel protocol user plane to generate a preset protocol data packet; The preset protocol data packet is taken as a payload to construct the transmission data packet based on a user datagram protocol.

[0010] Optionally, the base station uses the security layer to perform encryption processing on the transmission data packet to obtain an encrypted data packet, and sends the encrypted data packet to the core network user plane function through the anti-quantum secure channel, including: A post-quantum cryptographic algorithm is called by the security layer; The transmission data packet is encrypted according to the post-quantum cryptographic algorithm to generate the encrypted data packet; The encrypted data packet is sent to the core network user plane function through the anti-quantum secure channel according to the user datagram protocol; The post-quantum cryptographic algorithm is an encryption algorithm determined by negotiation in the handshake process of the security protocol.

[0011] Optionally, the core network user plane function uses the security layer to perform decryption processing and forwarding on the encrypted data packet, including: When the core network user plane function receives the encrypted data packet, it calls the post-quantum decryption algorithm corresponding to the post-quantum cryptography algorithm through the security layer. The encrypted data packet is decrypted according to the post-quantum decryption algorithm to obtain the original transmission data packet; Perform integrity verification on the transmitted data packets; Once the integrity verification passes, the service data in the transmitted data packet is forwarded to the target data network.

[0012] Optionally, the post-quantum cryptography algorithm includes a post-quantum key encapsulation mechanism and a post-quantum digital signature algorithm; wherein, the post-quantum key encapsulation mechanism is used to generate an encryption key and encrypt the transmitted data packet using the encryption key; the post-quantum digital signature algorithm is used to verify the identity information of the base station and the core network user plane function during the security protocol handshake process.

[0013] Secondly, the present invention provides a 5G user plane post-quantum secure transmission system, applied to a user data transmission path between a 5G user plane base station and a core network user plane function, wherein a security layer is deployed on the user data transmission path; the 5G user plane post-quantum secure transmission system includes: The channel establishment unit is used to establish a quantum-resistant secure channel by performing a handshake process of the security protocol through the security layer after the base station and the 5G core network user plane function access the network. An encapsulation unit is used to receive service data from a user through the base station and encapsulate the service data according to a preset protocol to obtain a transmission data packet of the service data. An encryption unit is used to encrypt the transmitted data packet using the security layer through the base station to obtain an encrypted data packet, and then send it to the core network user plane function. The forwarding unit is used to decrypt and forward the encrypted data packets using the security layer through the core network user plane function.

[0014] Thirdly, the electronic device of the present invention includes a memory and a processor; The memory is used to store computer programs; The processor is configured to implement the aforementioned 5G user plane post-quantum secure transmission method when executing the computer program.

[0015] Fourthly, the present invention provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the aforementioned 5G user plane post-quantum secure transmission method.

[0016] The present invention discloses a 5G user plane post-quantum secure transmission method, system, device, and medium. By deploying a security layer on the data transmission path and executing a security protocol handshake based on post-quantum cryptography, a quantum-resistant secure channel is established from the base station to the core network user plane function. This channel employs an algorithm resistant to quantum computing attacks for key negotiation and authentication during the establishment phase, replacing the asymmetric cryptography system in the traditional IPSec protocol that is vulnerable to quantum computer cracking. This makes the entire user plane data transmission foundation channel capable of resisting future quantum attacks. Furthermore, service data is encrypted by the security layer within the quantum-resistant secure channel at the base station. Since the session key used for encryption originates from the quantum-resistant channel negotiation and is inherently quantum-secure, even if the encrypted data packet is intercepted during transmission, attackers cannot use a quantum computer to crack the key. This mechanism ensures that the confidentiality of user service data is effectively protected against quantum computing.

[0017] This invention encapsulates and processes data within an established quantum-secure channel, and completes data transmission through authentication and decryption at the receiving end's security layer. Any tampering with the data packet will result in decryption failure, allowing the system to detect it instantly. This mechanism not only verifies that the data has not been tampered with during transmission but also authenticates the legitimate identity of the data sender, effectively resisting man-in-the-middle attacks and data tampering attacks based on quantum computing capabilities. Post-quantum security enhancement is achieved by adding a security layer between the base station and the core network user plane functions, without altering the existing 5G user plane protocol stack architecture and service processes. This embedded deployment approach provides excellent backward compatibility and implementability. Operators can smoothly introduce post-quantum security capabilities by upgrading or adding security network elements, significantly reducing deployment costs and complexity.

[0018] In summary, by introducing a security layer and a quantum-resistant secure channel, this invention systematically constructs a secure transmission mechanism that integrates quantum-resistant key negotiation, quantum-level encryption protection, integrity verification, and identity authentication. This effectively compensates for the security deficiencies of existing 5G user planes in dealing with quantum computing threats and provides stable security guarantees for user plane data transmission. Attached Figure Description

[0019] Figure 1 This is a flowchart illustrating the 5G user plane post-quantum secure transmission method according to an embodiment of the present invention. Figure 2 This is a schematic diagram of the 5G user plane protocol stack architecture with the introduction of a quantum security layer according to an embodiment of the present invention; Figure 3 This is a schematic diagram of the user plane data packet encryption transmission process of PQ-DTLS according to an embodiment of the present invention; Figure 4This is a schematic diagram of the structure of a 5G user plane post-quantum secure transmission system according to an embodiment of the present invention. Detailed Implementation

[0020] To make the above-mentioned objects, features, and advantages of the present invention more apparent and understandable, specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings. Although some embodiments of the present invention are shown in the drawings, it should be understood that the present invention can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of the present invention. It should be understood that the accompanying drawings and embodiments of the present invention are for illustrative purposes only and are not intended to limit the scope of protection of the present invention.

[0021] It should be understood that the various steps described in the method embodiments of the present invention may be performed in different orders and / or in parallel. Furthermore, the method embodiments may include additional steps and / or omit the steps shown. The scope of the present invention is not limited in this respect.

[0022] The term "comprising" and its variations as used herein are open-ended, meaning "including but not limited to"; the term "based on" means "at least partially based on"; the term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments"; and the term "optionally" means "optional embodiments". Definitions of other terms will be given in the following description. It should be noted that the concepts of "first," "second," etc., mentioned in this invention are used only to distinguish different devices, modules, or units, and are not intended to limit the order of functions performed by these devices, modules, or units or their interdependencies.

[0023] It should be noted that the terms "a" and "a plurality of" used in this invention are illustrative rather than restrictive. Those skilled in the art should understand that, unless otherwise expressly indicated in the context, they should be understood as "one or more".

[0024] It should be noted that the information (including but not limited to user device information, user personal information, etc.), data (including but not limited to data used for analysis, data stored, data displayed, etc.) and signals involved in this application are all authorized by the user or fully authorized by all parties. The collection, use and processing of related data must comply with the relevant laws, regulations and standards of the relevant countries and regions, and corresponding operation portals are provided for users to choose to authorize or refuse.

[0025] Combination Figure 1As shown in the figure, an embodiment of the present invention provides a post-quantum secure transmission method for 5G user plane, which is applied to the user data transmission path between the 5G user plane base station and the core network user plane function, wherein a security layer is deployed on the user data transmission path.

[0026] Specifically, this security layer is deployed on the N3 interface between gNB and UPF in the 5G user plane protocol stack, located between the UDP protocol and the GTP-U protocol, forming an independent software middleware or functional module, which achieves security protection by intercepting and enhancing GTP-U data packets.

[0027] The method includes: After the base station and the 5G core network user plane function access the network, a handshake process of the security protocol is performed through the security layer to establish a quantum-resistant secure channel.

[0028] Specifically, when the base station (gNB) and the core network user plane function (UPF) initiate communication, the security layer immediately triggers a handshake process based on post-quantum cryptography's Datagram Transport Layer Security Protocol (PQ-DTLS 1.3). This handshake process follows the IETF's TLS 1.3 post-quantum improvement standard and is adapted to the datagram transport layer. The gNB, acting as a client, sends a ClientHello message to the UPF. This message contains a list of supported post-quantum key encapsulation mechanisms (such as the Kyber algorithm or a hybrid scheme of traditional ECDH and post-quantum KEM) and post-quantum digital signature algorithms (such as the Dilithium algorithm). The UPF, acting as a server, responds with a ServerHello message, carrying the selected cipher suite, its own post-quantum public key parameters, and a digital signature generated using its post-quantum private key. Both parties exchange key shares and run the post-quantum KEM algorithm to generate a shared master key. Simultaneously, they utilize the post-quantum digital signature algorithm to complete two-way authentication, ensuring the authenticity of both communicating parties and their resistance to quantum attacks. After the handshake is complete, the security layer generates session keys at both ends, formally establishing a quantum-resistant secure channel.

[0029] The base station receives service data from users and encapsulates the service data according to a preset protocol to obtain the service data transmission data packet.

[0030] Specifically, when user data sent by the UE over the air interface arrives at the gNB after being protected by symmetric encryption, the gNB encapsulates it into a GTP-U protocol data unit. At this point, the security layer intercepts the GTP-U data packet and encrypts it according to the PQ-DTLS 1.3 protocol specification: first, a PQ-DTLS record layer header is added to the service data, indicating the content type, version number, and other information; then, a post-quantum authentication encryption algorithm (such as a hybrid scheme based on Kyber and Dilithium) negotiated during the handshake phase is used to encrypt the GTP-U payload and necessary header information, and an authentication tag is calculated; finally, the encrypted ciphertext, authentication tag, and PQ-DTLS record header are assembled into a complete PQ-DTLS protocol data unit, forming the data packet to be transmitted. This encapsulation process completely preserves the original GTP-U protocol structure, ensuring compatibility with existing 5G architectures.

[0031] The base station uses the security layer to encrypt the transmitted data packets, resulting in encrypted data packets, which are then sent to the core network user plane function.

[0032] Specifically, after completing PQ-DTLS encapsulation, the base station's security layer uses the session key negotiated during the handshake and a selected post-quantum encryption algorithm (such as a hybrid mode combining NTRU or Kyber key encapsulation mechanisms with symmetric encryption algorithms like AES-GCM) to perform encryption operations on the transmitted data packets, generating encrypted data packets. These encrypted data packets are sent to the UPF via the N3 interface using the UDP protocol. In this embodiment, PQ-DTLS-based datagram transmission eliminates the need for TCP's reliable transmission mechanism, fully meeting the low-latency, high-efficiency transmission requirements of 5G user plane. Furthermore, each data packet is independently encrypted, providing excellent forward security.

[0033] The encrypted data packets are decrypted and forwarded using the core network user plane functions and the security layer.

[0034] Specifically, after receiving encrypted data packets from the base station via the N3 interface, the UPF's security layer first parses the PQ-DTLS record header, extracts the encrypted data and authentication tag, performs decryption using the session key agreed upon with the base station and a post-quantum authentication encryption algorithm, recovers the original GTP-U data payload, and verifies the authentication tag to ensure data integrity and authenticity. If verification succeeds, the UPF security layer delivers the decrypted GTP-U data packet to the upper-layer protocol stack. The UPF then forwards the user data to the data network (such as the Internet or cloud services) via a UDP-based PDU session based on the destination information in the GTP-U header. If verification fails, the data packet is discarded and a security event is recorded. The entire decryption and forwarding process is completed automatically within the UPF's security layer, achieving secure transmission of user plane data from the base station to the core network and effectively resisting potential attacks in a quantum computing environment.

[0035] This embodiment of the 5G user plane post-quantum secure transmission method establishes a quantum-resistant secure channel from the base station to the core network user plane functions by deploying a security layer on the data transmission path and executing a secure protocol handshake based on post-quantum cryptography. During the establishment phase, this channel employs an algorithm resistant to quantum computing attacks for key negotiation and authentication, replacing the asymmetric cryptography system in traditional IPSec protocols that is vulnerable to quantum computer cracking. This makes the entire user plane data transmission foundation channel resistant to future quantum attacks. Furthermore, service data is encrypted by the security layer within the quantum-resistant secure channel at the base station. Since the session key used for encryption originates from the quantum-resistant channel negotiation and is inherently quantum-secure, even if the encrypted data packet is intercepted during transmission, attackers cannot use a quantum computer to crack the key. This mechanism ensures that the confidentiality of user service data is effectively protected against quantum computing.

[0036] This embodiment encapsulates and processes data within an established quantum-secure channel, and completes data transmission through authentication and decryption at the receiving end's security layer. Any tampering with the data packet will result in decryption failure, allowing the system to detect it immediately. This mechanism not only verifies that the data has not been tampered with during transmission but also authenticates the legitimate identity of the data sender, effectively resisting man-in-the-middle attacks and data tampering attacks based on quantum computing capabilities. Post-quantum security enhancement is achieved by adding a security layer between the base station and the core network user plane functions, without altering the existing 5G user plane protocol stack architecture and service processes. This embedded deployment approach provides excellent backward compatibility and implementability. Operators can smoothly introduce post-quantum security capabilities by upgrading or adding security network elements, significantly reducing deployment costs and complexity.

[0037] In summary, this embodiment systematically constructs a secure transmission mechanism that integrates quantum-resistant key negotiation, quantum-level encryption protection, integrity verification, and identity authentication by introducing a security layer and a quantum-resistant secure channel. This effectively compensates for the security deficiencies of existing 5G user planes in dealing with quantum computing threats and provides stable security for user plane data transmission.

[0038] Optionally, the step of establishing a quantum-resistant secure channel by performing a handshake process of a security protocol through the security layer after the base station and the 5G core network user plane function access the network includes: After the 5G user plane accesses the network, the handshake process corresponding to the security protocol is determined according to the security protocol of the datagram transport layer integrated in the security layer. The security protocol handshake process and two-way authentication are performed through the security layer. Once two-way authentication is complete, the quantum-resistant secure channel is established using the encryption algorithm parameters corresponding to the security protocol.

[0039] Specifically, on the N3 interface between the base station (gNB) and the user plane function (UPF) in the 5G user plane, the security layer integrates the post-quantum cryptography-based datagram transport layer security protocol (PQ-DTLS 1.3). This protocol is adapted from the IETF's TLS 1.3 post-quantum improvement standard and implemented through the WolfSSL open-source library. It replaces the key exchange algorithm in the traditional DTLS protocol with a post-quantum key encapsulation mechanism (such as the Kyber algorithm) or a hybrid post-quantum key encapsulation mechanism (such as the X25519+Kyber algorithm), and replaces the digital signature algorithm with a post-quantum signature algorithm (such as the Dilithium algorithm). When the gNB establishes a physical connection with the UPF and triggers user plane data transmission, the security layer automatically identifies the protocol type and initiates the PQ-DTLS 1.3 handshake process. This process follows the standard TLS 1.3 handshake framework, but all cryptographic operations use quantum-resistant algorithms to ensure security in a quantum computing environment.

[0040] As a client, gNB first sends a Client Hello message to UPF. This message contains a list of post-quantum cryptographic suites supported by gNB, a random number, and a digital signature of the message content using a Dilithium private key. Upon receiving the message, UPF verifies the validity of gNB's digital signature to confirm its identity, and then replies with a Server Hello message, carrying the selected cryptographic suite, UPF's post-quantum public key parameters, a random number, and a Dilithium digital signature generated using UPF's private key. After exchanging key shares, both parties run the Kyber key encapsulation algorithm to generate a shared master key and verify the integrity of the handshake through a Finished message. Throughout the process, two-way authentication is achieved through post-quantum digital signatures, ensuring the authenticity of both gNB and UPF's identities and resistance to quantum attacks, preventing man-in-the-middle attacks and identity forgery.

[0041] After a successful handshake, the PQ-DTLS protocol uses the negotiated cryptographic suite parameters (including key encapsulation mechanisms, symmetric encryption algorithms, authentication algorithms, etc.) to derive session keys at both the gNB and UPF security layers. These keys include a client-side write key for encrypting application data, a server-side write key, and an authentication key for integrity protection. These keys, based on a shared master key generated by a post-quantum key encapsulation mechanism, are derived using the HKDF key derivation function, thus possessing quantum-resistant security. The security layer then activates the encryption state, establishing a transparent quantum-resistant secure channel on the N3 interface. All GTP-U data packets passing through this channel are automatically encrypted without altering the upper-layer application logic, thereby achieving confidentiality, integrity, and quantum-resistant security for user plane data transmission.

[0042] In a preferred embodiment of the present invention, combined with Figure 2 As shown in the diagram, the left side vertically lists five 5G user plane network elements: UE (User Equipment), gNB (Ground Number NB), Intermediate-UPF (Intermediate User Plane Function), Anchor-UPF (Anchor User Plane Function), and Data Network, representing the complete data transmission path from the terminal to the destination network. At the air interface between the UE and gNB, the protocol stack is the Access Network Stack, including the L1 and L2 physical layers and the data link layer, as well as upper-layer air interface encryption mechanisms to protect data transmission between the UE and gNB. This is also true for the N3 interface between gNB and Intermediate-UPF, and between Intermediate-UPF and Anchor-UPF. Combined with... Figure 2As shown, a Post-Quantum DTLS security layer is inserted at a crucial location above the UDP / IP transport layer and below GTP-U (GPRS Tunneling Protocol-User Plane). This security layer is the implementation carrier of the Post-Quantum Cryptography-based Datagram Transport Layer Security Protocol (PQ-DTLS 1.3) mentioned earlier. It integrates the Kyber key encapsulation mechanism and Dilithium digital signature algorithm through the WolfSSL open-source library to provide end-to-end quantum-resistant encryption protection for user data (PDU) carried in the GTP-U tunnel. The GTP-U layer sits above Post-Quantum DTLS, indicating that the GTP-U protocol itself and its carried PDU user data are completely encapsulated within the PQ-DTLS payload, achieving transparent encryption enhancement of the existing GTP-U tunnel. Between the Anchor-UPF and the Data Network, the protocol stack is simplified to the standard UDP / IP protocol, used to forward the decrypted user data to the Internet or cloud services.

[0043] In this optional embodiment, by integrating the PQ-DTLS 1.3 protocol based on the IETF post-quantum improved standard and using the WolfSSL open-source library to completely replace the post-quantum cryptographic algorithm, the security failure problem of traditional cryptography in a quantum computing environment is fundamentally solved, enabling the 5G user plane to have quantum attack resistance for the first time. The two-way authentication mechanism in the handshake process makes up for the inherent defect of the lack of end-to-end authentication in the N3 interface of the existing 5G standard, effectively resisting man-in-the-middle attacks, identity forgery and signaling spoofing, and significantly improving the credibility of network-side communication. The shared master key negotiated based on the post-quantum key encapsulation mechanism, combined with the HKDF derivation algorithm to generate an independent session key, not only ensures the forward security of key exchange, but also realizes the one-time pad encryption mode, without relying on the TCP reliable transmission mechanism, greatly reducing handshake latency and meeting the millisecond-level latency requirements of the 5G user plane.

[0044] Optionally, the step of performing the security protocol handshake process and conducting two-way authentication through the security layer includes: Based on the security protocol, the identity information of the base station and the core network user plane function are exchanged, and the post-quantum cryptography algorithm is invoked through the security layer; The post-quantum cryptography algorithm performs two-way authentication based on the identity information of the base station and the core network user plane function.

[0045] Specifically, during the PQ-DTLS 1.3 handshake initialization phase, the base station (gNB), acting as a client, sends a Client Hello handshake message to the core network user plane function (UPF) through the security layer. This message carries the base station's identity information in plaintext, such as a pre-configured device certificate or public key identifier and a list of supported cipher suites, including different combinations of security parameters of the Kyber key encapsulation mechanism and the Dilithium digital signature algorithm, as well as parameters such as a 32-byte random number. The security layer uses the post-quantum cryptography algorithm interface encapsulated in the WolfSSL open-source library to calculate the Dilithium digital signature of the entire Client Hello message using the base station's private key, appends the signature value to the end of the message, and sends it together. After receiving the message, the UPF extracts the base station's identity identifier from the message, retrieves the corresponding Dilithium public key from the local trust store, and calls the WolfSSL verification interface to verify the signature, confirming the message integrity and the authenticity of the base station's identity. After successful verification, the UPF, acting as the server, also replies with a Server Hello message through the security layer. The message carries the UPF's identity information, the selected cipher suite, a random number, and a Dilithium signature generated using the UPF's private key. This message is then sent to the base station through the security layer. The base station's security layer performs the same signature verification process, completing the two-way exchange of identity information.

[0046] Based on the exchange of identity information, the core of the two-way authentication in this embodiment relies on the verification mechanism of the post-quantum digital signature algorithm. After receiving the Server Hello message returned by the UPF, the base station security layer extracts the UPF identity identifier and Dilithium signature, and uses the locally stored UPF public key to call the signature verification function of WolfSSL. If the verification is successful, the UPF identity is confirmed to be legitimate; otherwise, the handshake is terminated and an authentication failure alarm is reported. Similarly, the UPF has completed the verification of the base station's identity when it receives the Client Hello from the base station. When both parties have successfully verified each other's signatures, the security layer internally sets the authentication status to passed and enters the key exchange phase. At this time, the base station and the UPF use the Kyber public key parameters exchanged in the handshake message to run key encapsulation algorithms to generate a shared master key. The security layer uses this key and the random number in the handshake process to calculate an independent session encryption key through the HKDF derivation function, marking the formal completion of the two-way authentication based on the post-quantum cryptography algorithm. The two parties establish a trusted communication peer relationship, laying a secure foundation for subsequent encrypted data transmission.

[0047] In this optional embodiment, a post-quantum cryptography algorithm is invoked through the security layer, and the Dilithium digital signature algorithm is used to sign and verify the handshake messages of the user plane function between the base station and the core network. This solves the risk of identity forgery in the quantum computing environment of traditional public-key cryptography and realizes strong identity binding between the two communicating parties in the post-quantum era. This authentication mechanism specifically fills the inherent security shortcoming of the lack of end-to-end authentication in the N3 interface of the 3GPP standard, effectively resists man-in-the-middle attacks, signaling replay attacks and device spoofing attacks, and significantly improves the credibility and anti-attack capability of 5G core network user plane communication.

[0048] Optionally, the step of receiving service data from the user through the base station and encapsulating the service data according to a preset protocol to obtain a transmission data packet of the service data includes: The service data received from the user is received through the base station; the service data is communication data between the user equipment and the data network. According to the tunnel protocol, the user face encapsulates the service data to generate a preset protocol data packet; The preset protocol data packet is used as the payload to construct the transmission data packet based on the User Datagram Protocol.

[0049] Specifically, in the actual data transmission process of the 5G user plane, the user equipment (UE) sends uplink data to the base station (gNB) through the air interface (Uu interface). This air channel is protected by a symmetric encryption algorithm (such as the NEA algorithm) specified by the 3GPP standard to ensure the confidentiality of the air interface transmission. The access network protocol stack of the base station gNB receives and decrypts the data, recovering the original IP service data stream between the UE and the data network (such as the Internet, cloud services).

[0050] Additionally, it should be noted that the quantum-secure channel in this embodiment does not refer to the air interface channel between the UE and the gNB, but rather to the PQ-DTLS quantum-secure tunnel established between the gNB and the UPF. Service data received by the base station is temporarily stored in a buffer, awaiting processing at the security layer.

[0051] In a preferred embodiment of the present invention, combined with Figure 3The diagram illustrates a secure user plane data transmission scheme for a 5G access network according to an embodiment of the present invention. The English terms and their meanings in the diagram are: PDU (Protocol Data Unit), gNB (next generation NodeB, 5G base station), UPF (User Plane Function), and GTP-U (GPRS Tunneling Protocol for the User Plane). Figure 3 As shown, in the existing 5G user plane data flow, a PQ-DTLS (Post-Quantum Datagram Transport Layer Security) security layer mechanism is introduced between the gNB and UPF. The specific process is as follows: User Equipment (UE) and gNB transmit data via the air interface using symmetric encryption; after the data arrives at the gNB, it is encapsulated into plaintext GTP-U data packets; subsequently, the PQ-DTLS layer encrypts the payload of the GTP-U packet while keeping the GTP-U header unchanged, thus establishing a quantum-resistant secure tunnel between the gNB and UPF; finally, the UPF decrypts and verifies the received data and forwards the original service data to the target data network. This embodiment effectively improves the quantum computing attack resistance capability of 5G core network user plane data transmission without modifying the existing GTP-U protocol.

[0052] After receiving the raw service data, the security layer of the base station gNB calls the standard GTP-U (GPRS Tunneling Protocol-User Plane) processing module to encapsulate the service data according to the 3GPP TS 29.281 specification. The encapsulation process includes adding a GTP-U header to the original IP data packet. This header contains a TEID (Tunnel Endpoint Identifier) ​​field to identify the PDU session, a sequence number for packet ordering, and a length field, forming a GTP-U protocol data unit (PDU). This encapsulation process fully complies with existing 5G standards, does not change the GTP-U protocol format and function, and ensures compatibility with the core network UPF. The GTP-U tunneling protocol is based on plaintext transmission of UDP and has no built-in security mechanism. In this embodiment, a PQ-DTLS security layer is inserted after the plaintext GTP-U data packet is generated and before UDP encapsulation. Therefore, the generated preset protocol data packet is a standard GTP-U data packet, serving as the input payload for subsequent quantum-resistant encryption operations.

[0053] After GTP-U encapsulation is complete, the gNB's security layer immediately initiates the PQ-DTLS protocol processing flow. The security layer treats the entire GTP-U data packet, including the GTP-U header and its carried UE service data, as an application layer payload and encapsulates it according to the PQ-DTLS 1.3 record layer protocol format: First, a PQ-DTLS record header is added, indicating the content type, protocol version (0xFEFD indicates DTLS 1.3), and length field; then, the post-quantum encryption function from the WolfSSL open-source library is called, using the session key and authentication encryption algorithm negotiated during the handshake phase to encrypt the GTP-U payload and calculate the authentication tag; finally, the encrypted ciphertext, authentication tag, and PQ-DTLS record header are assembled into a complete PQ-DTLS protocol data unit. This PQ-DTLS PDU is then delivered to the lower-layer UDP protocol, where UDP headers such as source port, destination port, length, and checksum are added to form the final transmission data packet, which is sent to the UPF via the N3 interface. This construction process achieves end-to-end encryption protection for the GTP-U tunnel, and the generated UDP packets logically constitute the physical carrier of the quantum-secure channel.

[0054] In this optional embodiment, the base station receives user equipment service data from a quantum-secure channel and encapsulates it according to the GTP-U protocol in accordance with the 3GPP standard. This achieves full compatibility and transparent enhancement with the existing 5G user plane architecture without modifying the GTP-U protocol processing logic of the base station and the core network UPF, ensuring that existing network functions and service processes are not affected. The entire GTP-U data packet is encrypted and protected as a PQ-DTLS payload, and a UDP-based transmission data packet is constructed. This ensures that the N3 interface data, which was originally transmitted in plaintext, has end-to-end confidentiality and integrity protection, effectively resisting traffic eavesdropping, data tampering, and man-in-the-middle attacks. The PQ-DTLS datagram transmission mode avoids the additional delay and handshake overhead brought by the TCP reliable transmission mechanism, keeping the encrypted transmission latency in the millisecond range, and meeting the ultra-low latency service requirements of the 5G user plane.

[0055] Optionally, the step of encrypting the transmitted data packet using the security layer at the base station to obtain an encrypted data packet, and then sending it to the core network user plane function through the quantum-secure channel, includes: The post-quantum cryptography algorithm is invoked through the security layer; The transmitted data packet is encrypted according to the post-quantum cryptography algorithm to generate the encrypted data packet; According to the User Datagram Protocol, the encrypted data packet is sent to the core network user plane function through the quantum-secure channel; The post-quantum cryptography algorithm is the encryption algorithm negotiated and determined during the security protocol handshake process.

[0056] Specifically, upon receiving the transmission data packet to be processed—that is, the encapsulated GTP-U protocol data unit—at the security layer of the base station (gNB), the PQ-DTLS protocol encryption process is immediately triggered. The security layer invokes the post-quantum cryptography algorithm module through the pre-integrated WolfSSL open-source library interface. The invocation process in this embodiment includes: extracting the specific cipher suite parameters negotiated during the handshake phase from the security layer's session context, such as the Key Encapsulation Mechanism (KEM) type, digital signature algorithm, and symmetric encryption algorithm; based on the negotiation results, the WolfSSL library loads the corresponding post-quantum algorithm implementation and initializes the encryption context, preparing to perform encryption operations on the transmission data packet. This invocation process is fully automated, requiring no manual intervention, ensuring the immediacy and accuracy of the encryption operation.

[0057] After the quantum cryptography algorithm is invoked following the completion of the security layer, the symmetric encryption algorithm is first initialized using the session key derived from the handshake phase. Subsequently, the security layer takes the entire GTP-U data packet as plaintext input and feeds it into the encryption function for encryption, generating ciphertext data. Simultaneously, the AES-GCM algorithm calculates a 128-bit authentication tag to ensure data integrity and authenticity. After encryption, the security layer assembles the content type, protocol version (DTLS 1.3), length field, ciphertext data, and authentication tag sequentially according to the PQ-DTLS record layer protocol format, forming a complete PQ-DTLS encrypted data packet. This encrypted data packet converts the GTP-U payload into an unreadable ciphertext form, effectively resisting eavesdropping and analysis attacks.

[0058] After the encrypted data packet is generated, the security layer delivers it to the lower-layer UDP protocol stack. The UDP protocol stack adds a standard UDP header to the encrypted data packet, including the source port number (usually the default GTP-U port 2152 or a custom PQ-DTLS port), the destination port number, the PQ-DTLS port that the UPF is listening on, the UDP length, and a checksum field, forming the final UDP datagram. This UDP datagram is sent out through the N3 interface physical network between the base station and the UPF, typically via fiber optic or high-speed Ethernet. At this point, this logical channel established based on the PQ-DTLS protocol and using UDP as the transmission carrier is the aforementioned quantum-resistant secure channel, running through the entire N3 interface between the gNB and the UPF, ensuring that all encrypted data packets can be reliably transmitted to the UPF under post-quantum security protection.

[0059] During the PQ-DTLS 1.3 handshake phase, the base station and UPF negotiate and determine the final cipher suite to be used through Client Hello and Server Hello messages. This suite explicitly specifies the key encapsulation mechanism, such as Kyber-768, digital signature algorithms such as Dilithium-3, and symmetric encryption algorithms such as AES-256-GCM. These algorithm parameters are stored in the session context through a security layer and serve as the basis for encryption operations during data transmission. Each time the security layer invokes the post-quantum cryptographic algorithm, it follows the negotiated result to ensure the consistency of the encryption algorithm and avoid decryption failures due to algorithm mismatch, thereby guaranteeing the stable operation of the quantum-resistant secure channel.

[0060] In this optional embodiment, a post-quantum cryptography algorithm implemented by the WolfSSL library is invoked through the security layer. The session key is derived using the Kyber key encapsulation mechanism negotiated during the handshake and GTP-U data packets are encrypted using AES-256-GCM. This enables the N3 interface, which was originally transmitted in plaintext, to gain resistance to quantum attacks, effectively resisting the eavesdropping and decryption threats of future quantum computers. The encryption operation is applied directly to the GTP-U payload without changing its protocol header structure, achieving transparent enhancement to the existing 5G core network architecture and ensuring full compatibility with UPF. The encryption based on DTLS datagram mode avoids TCP overhead and meets the ultra-low latency requirements of the 5G user plane.

[0061] Optionally, the step of decrypting and forwarding the encrypted data packets using the security layer through the core network user plane function includes: When the core network user plane function receives the encrypted data packet, it calls the post-quantum decryption algorithm corresponding to the post-quantum cryptography algorithm through the security layer. The encrypted data packet is decrypted according to the post-quantum decryption algorithm to obtain the original transmission data packet; Perform integrity verification on the transmitted data packets; Once the integrity verification passes, the service data in the transmitted data packet is forwarded to the target data network.

[0062] Specifically, on the N3 interface, after the core network user plane function (UPF) listening port receives a UDP datagram sent by the base station (gNB), the UPF security layer first parses the UDP header and extracts the internal PQ-DTLS encrypted data packet. The security layer identifies the data packet as application data based on its content type, and then retrieves the cipher suite parameters negotiated during the handshake phase from the session context, including the key encapsulation mechanism (KEM), digital signature algorithm, and symmetric encryption algorithm information. Subsequently, the security layer calls the corresponding post-quantum decryption algorithm interface from the WolfSSL open-source library, loads the same session key used for encryption on the gNB side (derived from the Kyber key encapsulation mechanism and stored in the UPF security layer's memory), and initializes the authentication and decryption context, preparing to decrypt the encrypted data packet. The calling process in this embodiment is strictly symmetrical to the encryption call on the base station side, ensuring the consistency of the algorithm and key.

[0063] The security layer separates the ciphertext portion and authentication tag in the PQ-DTLS encrypted data packet, and uses the AES-256-GCM algorithm and session key to decrypt the ciphertext and recover the original plaintext GTP-U protocol data packet.

[0064] In this embodiment of the invention, the decryption process includes: first, verifying whether the data packet sequence number is within the valid window to prevent replay attacks; then, using an authentication tag to verify the integrity and authenticity of the ciphertext, confirming that the data has not been tampered with and indeed comes from a legitimate base station; after successful verification, the decryption function outputs a complete GTP-U data packet, including the GTP-U header and service data payload. Furthermore, the decryption operation is completed within the security layer, transparent to the upper-layer GTP-U protocol processing module of the UPF, and the obtained transmission data packet is completely consistent with the original GTP-U data packet before transmission by the base station, ensuring end-to-end data correctness.

[0065] After decrypting the original GTP-U data packet, the security layer performs two layers of integrity verification. Specifically, the first layer is the PQ-DTLS layer, where the authentication tag generated using the AES-GCM algorithm has been verified during decryption to confirm that the data has not been tampered with during transmission. The second layer is the GTP-U layer, where the security layer parses the GTP-U header, extracts the sequence number and length fields, and checks the integrity of the data packet according to the GTP-U protocol specification to confirm that there are no packet losses or out-of-order packets.

[0066] After verifying the integrity of the GTP-U data packet, the security layer delivers the decrypted GTP-U data packet to the upper-layer protocol stack of the UPF. The UPF parses the GTP-U header, locates the corresponding PDU session based on the TEID (Tunnel Endpoint Identifier), and extracts the original IP service data from the GTP-U payload. The UPF then queries the routing table based on the destination IP address to determine the data network egress interface and forwards the service data to its final destination, such as the Internet, a cloud server, or a private enterprise network, via the standard User Datagram Protocol (UDP). The forwarding process utilizes the UPF's existing data plane forwarding engine, requiring no modification to existing routing and forwarding logic. This decoupling of security and forwarding functions ensures that the UPF's high-performance data plane processing capabilities remain unaffected.

[0067] In this optional embodiment, the WolfSSL post-quantum decryption algorithm, which is completely symmetrical with the base station, is invoked at the security layer. The session key derived from the Kyber key encapsulation mechanism is used to decrypt the PQ-DTLS encrypted data packet, accurately recovering the original GTP-U data packet, thus realizing an end-to-end quantum-resistant secure transmission closed loop between the base station and the UPF. A dual integrity verification mechanism of AES-GCM authentication tag verification and GTP-U sequence number check is adopted to detect and discard tampered, replayed, or abnormally formatted data packets in real time at the data plane, effectively blocking malicious traffic from entering the core network and significantly improving the UPF's anti-attack capability. The decrypted data packet is transparently delivered to the UPF's original forwarding engine through a standard interface. The decoupling design of security functions and forwarding functions enables the UPF to obtain quantum-resistant security capabilities. Moreover, the entire decryption process is transparent to upper-layer applications, requiring no modification to the UPF routing logic or data network interface configuration, ensuring full compatibility with the existing 5G core network architecture. The security layer automatically logs and triggers alarms when verification fails, providing real-time security event monitoring capabilities for network operation and maintenance, and realizing end-to-end security reinforcement of user plane data transmission from the base station to the data network.

[0068] Optionally, the post-quantum cryptography algorithm includes a post-quantum key encapsulation mechanism and a post-quantum digital signature algorithm; wherein, the post-quantum key encapsulation mechanism is used to generate an encryption key and encrypt the transmitted data packet using the encryption key; the post-quantum digital signature algorithm is used to verify the identity information of the base station and the core network user plane function during the security protocol handshake process.

[0069] Specifically, in the PQ-DTLS 1.3 protocol, a post-quantum key encapsulation mechanism (such as the Kyber algorithm) is used to negotiate and generate a shared master key for both communicating parties during the handshake phase. The implementation is as follows: When the base station (gNB) sends a Client Hello message, it calls the Kyber key generation function from the WolfSSL open-source library through the security layer to generate a pair of temporary Kyber public and private keys, transmitting the public key in plaintext to the UPF. Upon receiving this, the UPF calls the Kyber encapsulation function, using the gNB's public key to encapsulate a randomly generated pre-master key, generating ciphertext which is then sent back to the gNB. The gNB uses its private key to call the Kyber decapsulation function to decrypt the pre-master key. Both parties then use the HKDF key derivation function, combined with the random number generated during the handshake process, to derive the session encryption key from the pre-master key. During the data transmission phase, the security layer calls symmetric encryption algorithms such as AES-256-GCM, using the derived encryption key to encrypt GTP-U data packets, generating encrypted data packets. This process combines post-quantum KEM with traditional symmetric encryption, leveraging Kyber's quantum resistance while maintaining the efficiency of the AES algorithm, ensuring the security of encryption keys against quantum attacks.

[0070] Post-quantum digital signature algorithms, such as the Dilithium algorithm, implement two-way authentication during the PQ-DTLS handshake. Specifically, the base station and the UPF (User-Defined Authentication and Handling) each generate a long-term key pair for the Dilithium algorithm using the WolfSSL library during factory manufacturing or network deployment, and pre-configure the public key in the other party's trust store. During the handshake, the base station sends a Client Hello message. The security layer calls the Dilithium signature function, using the base station's private key to digitally sign the entire handshake message, including the random number and cipher suite list, and appends the signature value to the end of the message. Upon receiving this, the UPF retrieves the base station's public key from the trust store and calls the Dilithium verification function to verify the signature validity, confirming that the message has not been tampered with and that the sender is indeed a legitimate base station. Similarly, the UPF signs the Server Hello message using the Dilithium private key, and the base station verifies the UPF signature to confirm the server's identity. Only after successful two-way signature verification can the handshake continue, thus achieving strong authentication between the communicating parties in the post-quantum era and effectively preventing man-in-the-middle attacks.

[0071] In this optional embodiment, a hybrid architecture combining post-quantum KEM negotiation keys and traditional efficient symmetric encryption is constructed through the Kyber key encapsulation mechanism and the Dilithium post-quantum digital signature algorithm implemented by the WolfSSL library at the security layer. This architecture leverages Kyber's quantum resistance to ensure the security of key exchange under quantum attacks while ensuring encryption efficiency through mature algorithms such as AES-256-GCM. The Dilithium signature verification mechanism achieves two-way identity authentication between the base station and the UPF during the handshake phase. Post-quantum security eliminates the risks of identity forgery and key leakage in traditional ECDSA / ECDH under quantum computing environments, effectively resisting man-in-the-middle attacks and device impersonation. The device pre-configured public key mechanism simplifies the deployment complexity of the PKI system, avoids real-time certificate query delays, and meets the millisecond-level latency requirements of 5G user plane.

[0072] Combination Figure 4 As shown, the present invention discloses a 5G user plane post-quantum secure transmission system, applied to the user data transmission path between a 5G user plane base station and a core network user plane function, wherein a security layer is deployed on the user data transmission path; the 5G user plane post-quantum secure transmission system includes: The channel establishment unit is used to establish a quantum-resistant secure channel by performing a handshake process of the security protocol through the security layer after the base station and the 5G core network user plane function access the network. An encapsulation unit is used to receive service data from a user through the base station and encapsulate the service data according to a preset protocol to obtain a transmission data packet of the service data. An encryption unit is used to encrypt the transmitted data packet using the security layer through the base station to obtain an encrypted data packet, and then send it to the core network user plane function. The forwarding unit is used to decrypt and forward the encrypted data packets using the security layer through the core network user plane function.

[0073] The advantages of the 5G user plane post-quantum secure transmission system of the present invention compared with the prior art are the same as the advantages of the above-mentioned 5G user plane post-quantum secure transmission method compared with the prior art, and will not be repeated here.

[0074] The electronic device of the present invention includes a memory and a processor; The memory is used to store computer programs; The processor is configured to implement the aforementioned 5G user plane post-quantum secure transmission method when executing the computer program.

[0075] The electronic device of the present invention has the same advantages over the prior art as the aforementioned 5G user plane post-quantum secure transmission method over the prior art, and will not be repeated here.

[0076] The present invention provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the aforementioned 5G user plane post-quantum secure transmission method.

[0077] The computer-readable storage medium of the present invention has the same advantages over the prior art as the aforementioned 5G user plane post-quantum secure transmission method over the prior art, and will not be repeated here.

[0078] While the present invention has been disclosed above, its scope of protection is not limited thereto. Those skilled in the art can make various changes and modifications without departing from the spirit and scope of the present invention, and all such changes and modifications will fall within the scope of protection of the present invention.

Claims

1. A method for post-quantum secure transmission in the 5G user plane, characterized in that, A user data transmission path between a base station and a core network user plane function applied to the 5G user plane, wherein a security layer is deployed on the user data transmission path; the post-quantum secure transmission method for the 5G user plane includes: After the base station and the 5G core network user plane function are connected to the network, a handshake process of the security protocol is performed through the security layer to establish a quantum-resistant secure channel; The base station receives service data from users and encapsulates the service data according to a preset protocol to obtain the service data transmission data packet. The base station uses the security layer to encrypt the transmitted data packet to obtain an encrypted data packet, which is then sent to the core network user plane function through the quantum-secure channel. The encrypted data packets are decrypted and forwarded using the core network user plane functions and the security layer.

2. The 5G user plane post-quantum secure transmission method according to claim 1, characterized in that, When the base station and the 5G core network user plane function access the network, the handshake process of the security protocol is performed through the security layer to establish a quantum-resistant secure channel, including: After the base station and the 5G core network user plane function access the network, the handshake process corresponding to the security protocol is determined according to the security protocol of the datagram transport layer integrated by the security layer. The security protocol handshake process and two-way authentication are performed through the security layer. Once two-way authentication is complete, the quantum-resistant secure channel is established using the encryption algorithm parameters corresponding to the security protocol.

3. The 5G user plane post-quantum secure transmission method according to claim 2, characterized in that, The process of performing the security protocol handshake and two-way authentication through the security layer includes: Based on the security protocol, the identity information of the base station and the core network user plane function are exchanged, and the post-quantum cryptography algorithm is invoked through the security layer; The post-quantum cryptography algorithm performs two-way authentication based on the identity information of the base station and the core network user plane function.

4. The 5G user plane post-quantum secure transmission method according to claim 1, characterized in that, The step of receiving service data from the user through the base station and encapsulating the service data according to a preset protocol to obtain the service data transmission data packet includes: The service data received from the user is received through the base station; the service data is communication data between the user equipment and the data network. According to the tunnel protocol, the user face encapsulates the service data to generate a preset protocol data packet; The preset protocol data packet is used as the payload to construct the transmission data packet based on the User Datagram Protocol.

5. The 5G user plane post-quantum secure transmission method according to claim 1, characterized in that, The step of encrypting the transmitted data packet using the security layer at the base station to obtain an encrypted data packet, and then sending it to the core network user plane function through the quantum-secure channel, includes: The post-quantum cryptography algorithm is invoked through the security layer; The transmitted data packet is encrypted according to the post-quantum cryptography algorithm to generate the encrypted data packet; According to the User Datagram Protocol, the encrypted data packet is sent to the core network user plane function through the quantum-secure channel; The post-quantum cryptography algorithm is the encryption algorithm negotiated and determined during the security protocol handshake process.

6. The 5G user plane post-quantum secure transmission method according to claim 5, characterized in that, The process of decrypting and forwarding the encrypted data packets using the security layer through the core network user plane function includes: When the core network user plane function receives the encrypted data packet, it calls the post-quantum decryption algorithm corresponding to the post-quantum cryptography algorithm through the security layer. The encrypted data packet is decrypted according to the post-quantum decryption algorithm to obtain the original transmission data packet; The integrity of the transmitted data packets is verified. Once the integrity verification passes, the service data in the transmitted data packet is forwarded to the target data network.

7. The 5G user plane post-quantum secure transmission method according to claim 5, characterized in that, The post-quantum cryptography algorithm includes a post-quantum key encapsulation mechanism and a post-quantum digital signature algorithm; wherein, the post-quantum key encapsulation mechanism is used to generate an encryption key and encrypt the transmitted data packet using the encryption key; the post-quantum digital signature algorithm is used to verify the identity information of the base station and the core network user plane function during the security protocol handshake process.

8. A 5G user plane post-quantum secure transmission system, characterized in that, A user data transmission path between a base station and a core network user plane function applied to the 5G user plane, wherein a security layer is deployed on the user data transmission path; the 5G user plane post-quantum secure transmission system includes: The channel establishment unit is used to establish a quantum-resistant secure channel by performing a handshake process of the security protocol through the security layer after the base station and the 5G core network user plane function access the network. An encapsulation unit is used to receive service data from a user through the base station and encapsulate the service data according to a preset protocol to obtain a transmission data packet of the service data. An encryption unit is used to encrypt the transmitted data packet using the security layer through the base station to obtain an encrypted data packet, and then send it to the core network user plane function. The forwarding unit is used to decrypt and forward the encrypted data packets using the security layer through the core network user plane function.

9. An electronic device, characterized in that, Including memory and processor; The memory is used to store computer programs; The processor is configured to, when executing the computer program, implement the 5G user plane post-quantum secure transmission method as described in any one of claims 1-7.

10. A computer-readable storage medium, characterized in that, The storage medium stores a computer program, which, when executed by a processor, implements the 5G user plane post-quantum secure transmission method as described in any one of claims 1-7.